According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."
Metrics
Affected Vendors & Products
References
History
Thu, 24 Jul 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google nest Cam \(indoor\, Wired\)
Google nest Cam \(indoor\, Wired\) Firmware Google nest Cam \(outdoor Or Indoor\, Battery\) Google nest Cam \(outdoor Or Indoor\, Battery\) Firmware Google nest Cam With Floodlight Google nest Cam With Floodlight Firmware Google nest Doorbell \(battery\) Google nest Doorbell \(battery\) Firmware |
|
CPEs | cpe:2.3:h:google:nest_cam_\(indoor\,_wired\):-:*:*:*:*:*:*:* cpe:2.3:h:google:nest_cam_\(outdoor_or_indoor\,_battery\):-:*:*:*:*:*:*:* cpe:2.3:h:google:nest_cam_with_floodlight:-:*:*:*:*:*:*:* cpe:2.3:h:google:nest_doorbell_\(battery\):-:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_\(indoor\,_wired\)_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_\(outdoor_or_indoor\,_battery\)_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_with_floodlight_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_doorbell_\(battery\)_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google nest Cam \(indoor\, Wired\)
Google nest Cam \(indoor\, Wired\) Firmware Google nest Cam \(outdoor Or Indoor\, Battery\) Google nest Cam \(outdoor Or Indoor\, Battery\) Firmware Google nest Cam With Floodlight Google nest Cam With Floodlight Firmware Google nest Doorbell \(battery\) Google nest Doorbell \(battery\) Firmware |
Wed, 02 Oct 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google nest Cam Battery Firmware Google nest Cam Floodlight Firmware Google nest Cam Indoor Firmware Google nest Doorbell Battery Firmware |
|
CPEs | cpe:2.3:o:google:nest_cam_battery_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_floodlight_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_indoor_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_doorbell_battery_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google nest Cam Battery Firmware Google nest Cam Floodlight Firmware Google nest Cam Indoor Firmware Google nest Doorbell Battery Firmware |
|
Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server." | |
Weaknesses | CWE-269 | |
References |
|

Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-10-02T14:06:33.704Z
Updated: 2024-10-02T17:00:33.323Z
Reserved: 2024-08-19T16:32:38.650Z
Link: CVE-2024-44097

Updated: 2024-10-02T17:00:26.112Z

Status : Analyzed
Published: 2024-10-02T14:15:05.670
Modified: 2025-07-24T15:58:43.047
Link: CVE-2024-44097

No data.